Confidential ยท 25 Jul 2026
๐ก๏ธ Daily Cybersecurity Briefing โ 2026-07-25 (Saturday)¶
Window: last 24โ48h (July 23โ25). Severity: ๐ด CRITICAL ยท ๐ก HIGH ยท ๐ข MEDIUM.
Threat level ELEVATEDVictims L30D 279Top actor QilinM&A L30D $36M
๐ผ M&A ACTIVITY¶
Cribl โ CardinalOps โ agentic detection engineering fills the AI-SOC gap (Jul 14)HighCribl acquired CardinalOps (Israel/US), developer of an AI-native detection-engineering platform that automates SIEM rule translation and coverage-gap analysis. Calcalist estimated deal value ~$100M; Cribl's new Tel Aviv R&D hub is anchored on this team. Cribl's data-movement platform gains automated SIEM modernization alongside the pipeline layer โ a full AI-SOC offering at a price point that competes with Palo Alto/Cortex XSIAM. GlobeNewswire ยท SecurityWeek
Cathedral โ $160M @ $1.4B โ military AI cyber (Jul 22)Mediuma16z and Sequoia led the round; Cathedral builds AI-native offensive and defensive cyber tooling for DoD/IC. Founded by ex-DOGE alumni. US News/Reuters
Glow โ $180M Series A @ $1.2B โ AI-native endpoint security (Jul 22)MediumSequoia, Cyberstarts, and Greenoaks led; founded by ex-Meta/Snowflake/Claroty team. AI-native endpoint security purpose-built for agentic workloads โ targets the coverage gap that traditional EDR has in AI agent environments. GlobeNewswire
Cisco Investments โ Zafran Security โ strategic round, >$140M total raised (Jul 22)MediumCisco validated Zafran's threat exposure management approach, which classifies 99% of critical CVEs as unexploitable in a given environment and focuses remediation effort on the 1% that matter. Operator-proof prioritization of patch workloads โ addresses the CVE triage bottleneck that Oracle's 1,449-CVE July CPU made vivid. Newswire
Risk Ledger โ $32M Series B โ supply-chain cyber, UK expansion (Jul 17)MediumAxiom Equity and Mercia led; network-first TPRM platform mapping supplier risk at depth rather than via questionnaires. SecurityWeek
Valarian โ $50M Series A โ sovereign AI compute infrastructure (Jul 13)MediumNEA led (first European defense-tech bet); builds air-gapped AI compute for defense and regulated sectors. SecurityWeek
No confirmed cybersecurity M&A or funding rounds surfaced for July 24โ25 (Friday may bring late disclosures).
L30D summary (Jun 25 โ Jul 25): 22+ named deals, ~$700M+ disclosed (many undisclosed). July volume: 18 named deals โ concentrated in AI-native detection (Glow, Glow, Cathedral, Cribl/CardinalOps, Zafran), composable/agentic SOC (Abstract Security, Cribl), and sovereign/military AI infrastructure (Cathedral, Valarian). June anchors now rolling off the window: Accenture/Dragos cluster ($4.17B) closed July 25's L30D boundary. Active consolidation theme: AI-native endpoint and detection tooling displacing incumbent SIEM/EDR, with venture capital pre-positioning for defense-tech demand from the Iran and Russia conflicts. Return on Security
โ ๏ธ CRITICAL BREACHES & INCIDENTS¶
Stadler Rail (Switzerland) โ Everest extortion, CHF 10M / $12.3M demand rejected โ no encryption, data-theft only โ Jul 21โ23HighSwiss rail-car manufacturer Stadler Rail disclosed that the Everest data-theft gang (no ransomware encryption deployed) breached a supplier-shared data-exchange platform used for technical documentation. Everest demanded CHF 10M (~$12.3M); Stadler refused, terminated the compromised platform, and filed a criminal complaint with Swiss authorities. No personal data was claimed exfiltrated; scope limited to technical/manufacturing data. Stadler's posture โ public refusal, criminal filing, and infrastructure shutdown โ sets a contrast with the majority of Everest victims who pay quietly. No DLS posting from Everest as of July 25. BleepingComputer ยท Help Net Security ยท The Record
Bank of Baroda (India) โ Triple X group, ~1 TB data claimed โ Jul 24 DLSHighThe Triple X ransomware group posted Bank of Baroda to its DLS on July 24, claiming ~1 TB of exfiltrated data with an estimated attack date of May 12, 2026. Bank of Baroda (government-owned, India's second-largest public-sector bank) has not confirmed or responded publicly. ๐ฅ Unverified DLS claim โ verify before treating as a confirmed breach. ransomware.live
Czech Philharmonic (Prague) โ TheGentlemen DLS claim โ Jul 23MediumTheGentlemen posted the Czech Philharmonic cultural organization on their DLS July 23. Data volume not yet disclosed. The targeting of a cultural heritage institution continues TheGentlemen's pattern of indiscriminate victim selection across sectors. ๐ฅ Unverified DLS claim. ransomware.live
AgentForger (ChatGPT Workspace AI Agents) โ single phishing link deploys invisible rogue AI agent inside target org โ Jul 24MediumSecurity researchers disclosed a critical vulnerability in OpenAI's ChatGPT Workspace AI Agents allowing an attacker to deploy an autonomous, invisible AI agent inside a victim organization via a single phishing link. The agent persists, exfiltrates data, and takes actions on behalf of the attacker. Scope: any organization using ChatGPT Workspace with AI agents enabled. No CVE assigned yet; OpenAI acknowledged and is investigating. SecurityWeek
๐ CRITICAL VULNERABILITIES¶
DEADLINE TODAY (Jul 25) โ CVE-2026-50522 (SharePoint, CVSS 9.8) + CVE-2026-16232 (Check Point SmartConsole, CVSS 9.3) โ federal agencies must remediate nowCriticalBoth KEV additions from July 22 hit their BOD 26-04 federal deadline today. CVE-2026-50522: SharePoint deserialization RCE, actively exploited; patching alone is insufficient โ IIS machine keys must be rotated post-patch as attackers steal them in a single pre-auth HTTP request. CVE-2026-16232: Check Point SmartConsole unauthenticated token theft granting full firewall-policy access โ exploitation requires network access to the Management Server IP. Federal agencies that have not remediated both are out of compliance as of today. CISA KEV ยท BleepingComputer SharePoint ยท Rapid7 Check Point
CVE-2026-6875 (CVSS 9.5) โ ServiceNow AI Platform pre-auth RCE โ actively exploited since Jul 18, NOT yet on CISA KEV โ affects 85% of Fortune 500CriticalUnauthenticated sandbox-escape RCE in ServiceNow's AI Platform Groovy scripting engine; a second exploit gadget chain was independently discovered, meaning signature-based defenses against the published PoC are insufficient. Hosted cloud instances were patched in April 2026; self-hosted instances only received patches July 13 (same day as public disclosure). Active exploitation began July 17โ19 โ five days after disclosure. CISA has not added this to KEV yet; the gap between confirmed exploitation and KEV addition is a live risk window for Fortune 500 firms and critical infrastructure operators. Patch KB3137947 applies immediately to all self-hosted instances. Help Net Security ยท BleepingComputer ยท SecurityAffairs
CVE-2026-54121 "Certighost" โ AD CS domain-takeover โ working PoC published Jul 24, CVSS 8.8HighResearchers H0j3n and Aniq Fakhrul published a working PoC July 24 for Certighost, an Active Directory Certificate Services flaw allowing any low-privileged domain user to impersonate a Domain Controller and achieve full domain compromise โ ESC15-class attack path. Patched in Microsoft's July 14 Patch Tuesday. The PoC's public release raises the exploit risk from "theoretical" to "script-kid accessible" for any environment that has not applied the July 14 patch. Cyber Kendra ยท GitHub PoC
LegacyHive Windows zero-day (Nightmare Eclipse) โ local privilege escalation via User Profile Service โ Jul 14, not yet on KEVHighThe threat actor "Nightmare Eclipse" (repeat Microsoft thorn) disclosed a local privilege escalation zero-day in the Windows User Profile Service allowing non-admin users to mount administrator registry hives and execute code when an admin logs in. PoC deliberately stripped; Microsoft is investigating. Not yet assigned a CVE or added to KEV. Impact: any Windows endpoint where a non-admin user can trigger admin login activity. SecurityWeek ยท BleepingComputer
๐จ INTELLIGENCE AGENCY ALERTS & POLICY¶
EO 14415 โ Defense supply-chain bill-of-materials mapping (Jul 20) โ scope extends to cloud providers and MSPsCriticalPresident Trump signed Executive Order 14415 requiring defense prime contractors to submit complete indentured bills of materials tracing all components, software, and raw materials to country of origin. The scope extends several supplier layers deep, including cloud providers and managed service providers serving the defense industrial base. Broader than traditional SBOM requirements โ explicitly covers software supply chains and services, not just hardware components. Organizations providing IT, security, or cloud services to DoD contractors should expect audit obligations downstream. White House EO 14415 ยท SecurityWeek
OFAC โ 1VPNS VPN provider + cryptor vendor designated under cyber EO (Jul 13)HighTreasury OFAC designated 1VPNS (First VPN Service) and its administrator Dmytro Rashevskyi for providing anonymization infrastructure specifically marketed and sold to ransomware groups; separately designated Yegeniy Vladimirovich Silayev for selling commercial cryptors used to disguise ransomware payloads against AV/EDR. Both designated under EO 14390 (Trump's March 2026 cybercrime EO). This is the clearest public action yet against cybercrime-enabling infrastructure vendors. Treasury SB0559
UK โ PM Andy Burnham reappoints Liz Lloyd as cybersecurity minister โ continuity confirmedMediumFollowing Andy Burnham's accession as Prime Minister (~Jul 20), Lloyd was reappointed in an equivalent cybersecurity role, continuing to steer the UK's National Cyber Security Bill through Parliament. Policy continuity on the legislation โ the most significant UK cyber regulatory update in a decade. The Record
๐ THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS movement (July 24โ25):
TheGentlemenHigh6+ new DLS postings July 24: Czech Philharmonic (Prague), Conecsus LLC (US), Agapit, and others. Running total: 483+ cumulative victims across 66 countries, with 117 claimed in June alone (highest single-month count by any group since mid-2025). Q2 2026: 284 attacks โ combined with Qilin (299 attacks), the pair account for 583 Q2 attacks, outpacing the next five groups combined. GuidePoint Q2 2026 ยท Security Boulevard
Triple XHighBank of Baroda posted July 24 (~1 TB). A relatively new group targeting financial sector; government-owned Indian banks have not been a frequent target historically. ๐ฅ Unverified DLS claim.
QilinHighCorporate 360 Business Solutions and AppleOne Properties Inc. posted July 24. Qilin l12m: 1,496+ victims; still #1 by volume per Bitdefender. ransomware.live
InsomniaMediumBrooklyn Defender Services posted July 24 (estimated attack date May 29). Legal-services sector; Brooklyn Defender Services provides public defender services in New York City. ๐ฅ Unverified DLS claim.
APT / nation-state:
Laundry Bear (Russia, GRU)CriticalDutch MIVD Director clarified July 24 that Laundry Bear's Zimbra zero-click campaign (CISA AA26-204A) is specifically targeting information about "the purchase and production of military equipment" for NATO/Ukraine allies โ pre-conflict targeting-list construction at automated scale. Advisory now co-signed by 16 nations. Any unpatched Zimbra Collaboration Suite Classic UI (pre-v10.1.13) is currently actively exploited. CISA AA26-204A ยท NCSC-UK
UAT-8616 (unattributed sophisticated actor)HighCVE-2026-20245 (Cisco Catalyst SD-WAN Manager privilege escalation) exploited as a zero-day at least two months before the patch, with sophisticated anti-forensic cleanup on compromised devices (Mandiant attribution). This is the seventh Cisco SD-WAN zero-day exploited in 2026 โ Cisco's SD-WAN surface has become a systematic targeting priority for sophisticated actors. SecurityWeek
๐ GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Laundry Bear's weapons-procurement focus (MIVD July 24 statement) makes the Zimbra campaign categorically different from typical credential-harvesting: GRU is conducting automated pre-conflict ISR against the supply chains that keep Ukraine armed, not just collecting diplomatic mail.CriticalThe Dutch MIVD Director's explicit public statement โ that the group is targeting information about "the purchase and production of military equipment" โ removes the ambiguity about what Laundry Bear is building toward. Zero-click, 90-day email archive exfiltration from NATO government and defense-adjacent commercial accounts creates a near-real-time picture of weapons delivery schedules and production capacity. Executives at defense contractors, logistics firms, and financial institutions handling Ukraine-related transactions should treat Zimbra patching and migration as a supply-chain security obligation, not just an IT maintenance item. CISA AA26-204A ยท NCSC-UK
EO 14415's supply-chain bill-of-materials requirement (signed Jul 20) extends accountability for Chinese component exposure from prime contractors three or four supplier layers deep โ the first regulation that formally reaches cloud providers and MSPs inside the defense supply chain.HighTraditional SBOM requirements applied to software delivered in products; EO 14415 covers services, cloud compute, and managed services consumed by defense contractors. For cybersecurity and IT service providers with DoD-adjacent customers, this creates audit obligations that did not exist a week ago. The order arrives as the semiconductor export control regime (H200 chips to China: banned, unbanned, now tariffed) signals that the Trump administration is using regulatory enforcement rather than new bans as the primary China-tech-decoupling mechanism. White House EO 14415 ยท SecurityWeek
Iran's cyber posture (war day 147) remains structurally intact despite the February strikes that killed senior IRGC leadership โ MuddyWater and FAD Team continue to operate, and the July 22 AA26-097A update adding new IoCs for Rockwell PLC manipulation suggests active preparation, not just capability maintenance.HighFBI observed new malicious PLC project-file deployments in the July 22 update window; the expansion from Rockwell targets to Siemens and Schneider Electric hardware broadens the critical-infrastructure attack surface. No confirmed retaliatory cyber event has materialized in day 147, but the Hornets' Nest pattern โ persistent pre-positioning on ICS targets โ is historically followed by activation when additional diplomatic or military escalation occurs. Energy and water sector OT operators should review CISA AA26-097A indicators regardless of whether they perceive themselves as politically relevant targets. CISA AA26-097A ยท SOCRadar
The OFAC designation of 1VPNS (a VPN sold specifically to ransomware groups for 12+ years) and a commercial cryptor vendor signals a shift in the US counter-ransomware economic model: sanctions pressure is moving up the criminal supply chain from the ransomware operators themselves to the infrastructure enablers who give those operators operational reach.HighNaming the VPN provider that shielded groups like LockBit and Conti creates precedent for designating privacy-tool vendors who knowingly service criminal actors, a category previously treated as legally ambiguous. Combined with the visa restrictions on Southeast Asia scam-center operators announced from Manila (July 23), this is the clearest articulation yet that the US is targeting the criminal-state infrastructure nexus rather than individual operators who are difficult to extradite. Treasury SB0559 ยท The Record
Hong Kong EO 13936 expiry (July 17) and the partial OFAC SDN list reductions signal a calibrated US-China de-escalation gesture โ but semiconductor export control enforcement, not new restrictions, is the operative pressure tool this quarter.MediumThe Trump administration removed 9 persons from the SDN list and moved 39 to a lower-impact sanction tier as Beijing welcomed the HK-related EO lapse. Simultaneously, Commerce is enforcing existing H200 licensing requirements aggressively rather than announcing new chip bans, following a 12-month cycle of conflicting signals that undermined US credibility with allied chip manufacturers. The net effect: the de-escalation optics are managed, but Chinese AI development access to high-end semiconductors remains the contested variable. Steptoe Sanctions Update ยท East Asia Forum
M&A activity
Socure โ Fravityโ
Brinqa โ PlexTracโ
Munich Re (via HSB) โ $575Mโ
Fortinet โ Virtue AIโ